hi-vpn

PRIVACY · EFFECTIVE 2026-07-28

Your data with us
fits in one small table.

The full policy is below, but start with this table — it is everything in our database about you. Jurisdiction protects no one; only not holding data does. Heidi Technology, Inc. is a Delaware (USA) corporation and account data lives in the United States (Oregon).

WE STORE
EmailAccount identity, service notices
Stripe customer IDSubscription status and refunds
Credential hashesNodes authenticate your devices
Connection country codeDetect credential sharing (2 letters — no city, no IP)
NO SUCH FIELD
Client IPdoes not exist
Connection historydoes not exist
DNS queriesdoes not exist
Traffic contentsdoes not exist

Retention

Current connection stateOverwritten by the next heartbeat
Revoked credential hashes30 days
After account deletionPurged within 30 days
Stripe transaction recordsKept per law — outside our control

Government and legal requests

We respond to valid legal process with proper jurisdiction. But because we do not log client IPs, wecannot map a connection to a person — we will not start logging in order to answer a request, and we will not name users based on guesswork.

Heidi Technology, Inc. ("Heidi," "we," "us," or "our"), a Delaware corporation, operates the hi-vpn service (the "Service"). This Privacy Policy explains what information we collect, what we deliberately do not collect, and how we handle it. Privacy is the core purpose of our Service — we have designed hi-vpn to collect as little information about you as technically possible.

1. What we do NOT collect or log

We do not record, store, or log:

We cannot provide information we do not have. If we receive a legal request for such data, we are unable to produce it because it does not exist. There is no client-IP column and no connection-history table in our database. Node heartbeats parse an allowlist of fields — any extra IP field is dropped; GeoIP lookups happen only on the node itself, and the raw IP is discarded immediately after the lookup, never sent to the control plane.

2. What we DO collect

To operate the Service, provide support, and process payments, we collect:

Account information

Payment information

When you subscribe through our website, payments are processed by Stripe. We do not receive or store your full card number; we retain your subscription status, plan, and transaction identifiers. If we later offer subscriptions through the Apple App Store or Google Play, those platforms process payment and provide us only a subscription/transaction identifier and status.

Aggregate and operational data

We record aggregate usage data necessary to operate and bill the Service: concurrent-connection counts per account (for plan enforcement and to detect prohibited account sharing), the two-letter country code of connections (no city, no IP), and aggregate, non-identifying server load metrics. This data reflects how much you use the Service, not what you do with it.

3. How we use information

We do not sell your personal information. We do not use your data for advertising.

4. Third parties we share data with

ProviderPurposeData shared
StripeWebsite payment processingEmail, subscription data
Apple / GoogleApp store subscriptions (if listed)Subscription/transaction identifiers
SupabaseDatabase and authenticationThe account data listed on this page
CloudflareDNS and bot protectionOperational data only
VPN node providersServer hostingNo personally identifying data stored on nodes

We may disclose information if required by a valid legal process that applies to us — but we can only disclose data we actually hold (see Section 1).

5. Data retention

Current connection state is overwritten by the node's next full report after disconnect. Revoked credential hashes are kept for 30 days to handle billing disputes, then deleted by a scheduled job. After account deletion, email and credential data are purged within 30 days; transaction records that Stripe retains under its legal obligations are outside our control. The categories in Section 1 are not retained at all — they are never collected.

6. Your rights

Your account page shows every field we hold about you, and you can export or delete your account at any time — deletion is real deletion, not a flag. Depending on your location, you may have rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA), including the right to access, correct, delete, or export your personal data. To exercise these rights, contactprivacy@hi-vpn.com. We will respond within the timeframe required by applicable law; note that the data in Section 1 does not exist and therefore cannot be produced.

7. Data storage location

Account data is stored in the United States (Oregon). By using the Service, you understand your information may be processed in jurisdictions other than your own.

8. Children

The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child under 16 has an account, contactprivacy@hi-vpn.com and we will delete the data.

9. Changes

We may update this Policy. Material changes will be communicated through the Service or by email 30 days before they take effect, with full version history retained. Continued use after changes take effect constitutes acceptance.

10. Contact

Heidi Technology, Inc.
1201 North Market Street Suite 111, Wilmington, DE 19801
Privacy inquiries:privacy@hi-vpn.com